View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

Google warns of new Chrome zero-day flaw exploited in attacks

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • OpenPanel before 2.3.0 vulnerable to unauthenticated SSRF via favicon and og endpoints
    OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in its favicon and og endpoints.

    • Affects OpenPanel deployments running versions before 2.3.0
    • Unauthenticated server-side request forgery (SSRF) vulnerability in the /misc/favicon and /misc/og endpoints
    • Endpoints accept an attacker-supplied url parameter with insufficient validation
      ๐Ÿ“Ž Coverage: cve.threatint.com ยท ๐Ÿ‘ via CVE ThreatInt
  • OpenPanel before 2.3.0 vulnerable to cross-tenant BOLA via report tRPC procedures
    OpenPanel before 2.3.0 contains a cross-tenant broken object level authorization vulnerability in its report tRPC procedures.

    • Affects OpenPanel deployments running versions before 2.3.0.
    • The report.getLayouts and report.resetLayout tRPC procedures contain a cross-tenant broken object level authorization (BOLA) vulnerability.
    • The procedures fail to scope dashboard queries to the requesting tenant, enabling cross-tenant access to dashboard data.
      ๐Ÿ“Ž Coverage: cve.threatint.com ยท ๐Ÿ‘ via CVE ThreatInt
  • Microsoft Confirms New Exchange Online Outage Delaying Emails from External Domains
    Microsoft has confirmed a new Exchange Online outage that is delaying emails sent to and from external domains.

    • The outage affects Microsoft Exchange Online, one of the most widely used business email platforms.
    • The incident, tracked as EX1467029, is causing delays for users sending and receiving email messages from external domains.
    • Microsoft flagged the issue as a service degradation and first acknowledged the disruption on September 4, 2026.
      ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News, cryptika.com (discovered)
  • Microsoft 365 Phishing Bypasses Direct Send Blocking via Blank SMTP Envelope Sender
    Phishers are leaving the SMTP envelope sender blank to slip unauthenticated messages past Microsoft 365's Direct Send blocking.

    • Affects Microsoft 365 users and organizations relying on Direct Send safeguards to block unauthenticated inbound email.
    • Phishing emails display a sender address that appears to belong to the recipient's own organization.
    • The technique works by omitting the SMTP envelope sender entirely, which can let unauthenticated messages pass Direct Send blocking.
    • It is an abuse of protocol behavior, not a Microsoft software flaw, so no CVE or patch is associated with it.
      ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News, cryptika.com (discovered)
  • New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges (one-liner) โ€” <https://www.bleepingcomputer.com/news/security/new-crowdstrike-falconflank-zero-day-grants-system-privileges/|BleepingComputer>

  • Exchange Online outage causes email delays, 'Server busy' errors (one-liner) โ€” <https://www.bleepingcomputer.com/news/microsoft/exchange-online-outage-causes-email-delays-server-busy-errors/|BleepingComputer>

  • Google warns of new Chrome zero-day flaw exploited in attacks (one-liner) โ€” <https://www.bleepingcomputer.com/news/security/google-warns-of-new-chrome-zero-day-flaw-exploited-in-attacks/|BleepingComputer>

  • 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover (one-liner) โ€” <https://www.securityweek.com/12-year-old-postgresql-vulnerability-enables-database-server-takeover/|SecurityWeek>

  • Catch Raises $5 Million for AI Executive Assistant With Guardrails (one-liner) โ€” <https://www.securityweek.com/catch-raises-5-million-for-ai-executive-assistant-with-guardrails/|SecurityWeek>

  • VMware Workstation and Fusion Updates Patch Critical Vulnerability (one-liner) โ€” <https://www.securityweek.com/vmware-workstation-and-fusion-updates-patch-critical-vulnerability/|SecurityWeek>

  • Google Patches 6th Chrome Zero-Day of 2026 (one-liner) โ€” <https://www.securityweek.com/google-patches-6th-chrome-zero-day-of-2026/|SecurityWeek>

  • Nvidia Is Buying AI Platform Hugging Face for $13 Billion (one-liner) โ€” <https://www.securityweek.com/nvidia-is-buying-ai-platform-hugging-face-for-13-billion/|SecurityWeek>

  • Security Vulnerability in a Voting System (one-liner) โ€” <https://www.schneier.com/blog/archives/2026/09/security-vulnerability-in-a-voting-system.html|Schneier on Security>

  • AI Is Ending the Era of Hidden Vulnerabilities โ€” Are Vendors Ready? (one-liner) โ€” <https://www.darkreading.com/vulnerabilities-threats/ai-ending-era-hidden-vulnerabilities-are-vendors-ready|Dark Reading>

  • SQL Injection in TAC Information's GoldenHornImproper neutralization of speci... (one-liner) โ€” <https://cve.threatint.com/CVE/CVE-2026-18198?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>

  • Username Enumeration in Menulux Software's Menulux PortalObservable response ... (one-liner) โ€” <https://cve.threatint.com/CVE/CVE-2026-19080?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>

  • Plaintext Storage of User Credentials in Menulux Software's Menulux PortalPla... (one-liner) โ€” <https://cve.threatint.com/CVE/CVE-2026-19051?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>

  • Authorization Bypass Critical POS Management Functions in Menulux Software's ... (one-liner) โ€” <https://cve.threatint.com/CVE/CVE-2026-19043?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>

  • Stored XSS in Menulux Software's Menulux PortalImproper neutralization of inp... (one-liner) โ€” <https://cve.threatint.com/CVE/CVE-2026-18957?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>

  • snipe-it before 8.6.3 Authorization Bypass via Bulk Deletesnipe-it versions b... (one-liner) โ€” <https://cve.threatint.com/CVE/CVE-2026-85617?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>

  • Snipe-IT before 8.6.2 Authorization Bypass via Checkout-AcceptanceSnipe-IT ve... (one-liner) โ€” <https://cve.threatint.com/CVE/CVE-2026-85616?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>

  • Openpanel before 2.3.0 Cross-Tenant IDOR via report.getLayoutsOpenpanel befor... (one-liner) โ€” <https://cve.threatint.com/CVE/CVE-2026-85615?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>

  • OpenPanel API before 2.3.0 Unauthenticated SSRF via site-checkerOpenPanel bef... (one-liner) โ€” <https://cve.threatint.com/CVE/CVE-2026-85614?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>

  • OpenPanel Unauthenticated XSS via SVG Favicon ProxyOpenPanel before 2.3.0 con... (one-liner) โ€” <https://cve.threatint.com/CVE/CVE-2026-85613?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>

  • OpenPanel before 2.3.0 Remote Code Execution via chart formulasOpenPanel befo... (one-liner) โ€” <https://cve.threatint.com/CVE/CVE-2026-85610?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>

  • Openpanel before 2.3.0 SSRF via Site Checker EndpointOpenpanel before 2.3.0 c... (one-liner) โ€” <https://cve.threatint.com/CVE/CVE-2026-85609?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>

  • Grav before 2.0.19 Remote Code Execution via sort filterGrav before 2.0.19 (a... (one-liner) โ€” <https://cve.threatint.com/CVE/CVE-2026-85604?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>

  • Grav Admin Plugin Path Traversal via Save As Language CodeGrav versions befor... (one-liner) โ€” <https://cve.threatint.com/CVE/CVE-2026-85603?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>

  • Grav Form Plugin before 9.1.20 reCAPTCHA v3 Authentication BypassThe Grav For... (one-liner) โ€” <https://cve.threatint.com/CVE/CVE-2026-85602?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>

  • Grav Admin before 2.0.20 Cross-Site Scripting via marked.jsGrav Admin before ... (one-liner) โ€” <https://cve.threatint.com/CVE/CVE-2026-85601?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>

  • Grav Admin before 2.0.21 Stored XSS via usernameGrav Admin (getgrav/grav-plug... (one-liner) โ€” <https://cve.threatint.com/CVE/CVE-2026-85600?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>

  • Grav Shortcode Core before 6.2.5 Stored XSS via unescaped parametersGrav Shor... (one-liner) โ€” <https://cve.threatint.com/CVE/CVE-2026-85599?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>

  • I can't believe The Register ran my quote, lol - kudos. (one-liner) โ€” <https://cyberplace.social/@GossiTheDog/117212745759654125|@GossiTheDog@cyberplace.social>

  • If you work for Google or Microsoft in security, ask internally what the browser teams are doing about it. (one-liner) โ€” <https://cyberplace.social/@GossiTheDog/117212722433258360|@GossiTheDog@cyberplace.social>

  • Obvious point - browser makers (hi Google and Microsoft) should have this stuff built in. (one-liner) โ€” <https://cyberplace.social/@GossiTheDog/117212711615780511|@GossiTheDog@cyberplace.social>
    โš ๏ธ

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check